Does a Small Business Need a Data Protection Officer (DPO)?
The honest answer for most small businesses is no — a statutory DPO is mandatory in only three situations. Here is how to tell which side of the line you're on, and what to do either way.
The short version
- A statutory DPO is mandatory in only three situations under UK GDPR Article 37 — public authorities, large-scale regular and systematic monitoring of people, or large-scale processing of special-category or criminal-offence data.
- Most ordinary small businesses meet none of them. Running payroll or holding a customer list is not a 'core activity' of large-scale monitoring, so most SMEs are not legally required to appoint one.
- You should still give someone clear responsibility for data protection — a data protection lead — even though that's good practice, not the statutory DPO role.
- 'Do I need a DPO?' is not a reason to stall. The basics of knowing what you hold and protecting it apply to every business regardless of the answer.
If you’ve come across “you might need a Data Protection Officer” and felt a flicker of worry, you can probably relax. The question do I need a DPO has a reassuring answer for most small businesses: almost certainly not, at least not the formal, legally-required version. UK GDPR makes a statutory DPO mandatory in only three specific situations, and ordinary trading businesses rarely fall into any of them. The trick is knowing the difference between the legal role and the sensible everyday practice that every business should follow.
What a Data Protection Officer actually is
A DPO is a specific statutory role under UK GDPR, an independent expert who oversees how an organisation handles personal data, not just a job title you can hand to whoever has spare time.
The term gets used loosely, which is where the confusion starts. A Data Protection Officer in the legal sense is a defined position with defined duties: monitoring compliance with data protection law, advising the organisation, training staff, and acting as the contact point for the ICO (the Information Commissioner’s Office, the UK’s data protection regulator) and for the people whose data you hold.
Crucially, the role carries protections and conditions. A statutory DPO must be able to act independently, report to your most senior level, and avoid any conflict of interest. That’s a real commitment, which is exactly why the law only requires it where the risk to people genuinely warrants it. For most small businesses, calling someone your ‘data protection lead’ is the right move. Calling them a DPO when the law doesn’t require one means signing up to obligations you don’t actually have.
The three legal triggers, in plain English
Article 37 of the UK GDPR makes a DPO mandatory in exactly three situations, and unless your business clearly fits one, you are not legally required to appoint one.
Here are the three, stripped of the legal phrasing:
- You are a public authority or body. Councils, schools, NHS bodies and similar public organisations must appoint a DPO, whatever data they handle. Courts acting in their judicial capacity are the one carve-out. If you run a private business, this one doesn’t apply to you.
- Your core activities require large-scale, regular and systematic monitoring of people. This is about businesses whose main purpose involves tracking or profiling individuals at scale: think continuous behavioural tracking, large-scale location monitoring, or profiling for targeted advertising as the actual product.
- Your core activities involve large-scale processing of special-category or criminal-offence data. Special-category data is the sensitive stuff: health, racial or ethnic origin, religious or philosophical beliefs, sex life or sexual orientation, and biometric and genetic data. A large private hospital or a national health-screening service would be in this bracket. A café that keeps a note of a customer’s nut allergy is not.
Two ideas do almost all the heavy lifting in triggers two and three: core activities and large scale. Get those right and the answer usually becomes obvious.
Why “core activities” lets most small businesses off
Processing you do as a routine side-effect of running a business — payroll, a customer list, staff HR files — is not a ‘core activity’, so it doesn’t trigger the DPO requirement.
This is the single most misunderstood part of the test, and it’s the part that reassures most owners once they grasp it.
The ICO draws a clear line. Your core activities are the things you do to achieve your primary objectives, the heart of what your business is for. A debt-recovery firm’s core activity is processing debtor data. A market-research company’s core activity might be profiling consumers. By contrast, processing you do all the time but only to keep the lights on (paying your staff, holding a list of customers so you can invoice them, keeping HR records) is a secondary purpose, not a core activity.
So a plumber, an accountancy practice, a small marketing agency, a corner shop, a builder, a local solicitor: they all process personal data daily, but that processing is incidental to the trade itself, not the trade itself. None of them is in the business of large-scale monitoring or large-scale sensitive-data processing. None of them needs a statutory DPO.
A QUICK GUT CHECK
Ask yourself one question: is large-scale tracking of people, or large-scale handling of sensitive data, the actual thing my business sells or does? If the honest answer is no, and you just hold normal customer and staff records to run a normal business, you almost certainly don't need a statutory DPO. If you're genuinely unsure because monitoring or sensitive data is central to your model, that's the moment to take proper advice.
Who does need one: a few real examples
A handful of business types do cross the line, and they’re the ones where tracking people or handling sensitive data at scale is the point of the business.
It helps to see both sides. Businesses that genuinely do tend to need a DPO include:
- A company whose product is large-scale online behavioural tracking or ad-profiling.
- A health-tech firm processing patient health records for many thousands of people.
- An organisation running large-scale background checks or handling criminal-records data as its main service.
- A security firm operating extensive monitoring or surveillance systems across many sites.
Businesses that almost never need one include the everyday majority: retailers, trades, professional services, hospitality, small agencies, e-commerce shops selling ordinary goods. They hold personal data, sometimes a fair amount of it, but it’s the ordinary plumbing of doing business, not large-scale monitoring or large-scale sensitive processing.
The DPO question isn’t really ‘how much data do I hold?’. It’s ‘is watching or handling people’s most sensitive data the actual job?’. For most small businesses, the answer is a clear no.
What to do instead: name a data protection lead
Even when the law doesn’t require a DPO, you should still give one named person clear responsibility for data protection. It’s good practice, and it’s where real protection actually comes from.
Not needing a statutory DPO is not the same as no one being responsible. The opposite, in fact. The ICO encourages every organisation to make sure someone has clear ownership of data protection, even where a formal DPO isn’t required.
This person is sometimes called a data protection lead or manager — a deliberately lighter role than the statutory DPO: no formal independence requirement, no obligation to report to board level, no rule against conflicts of interest. In a small business it’s often the owner, the office manager, or whoever already keeps an eye on systems and records. What matters is that the responsibility is named and understood, not floating vaguely across everyone and therefore nobody.
A good data protection lead does the practical work that actually keeps you compliant: knowing what personal data you hold and where, keeping your privacy notice and basic GDPR housekeeping up to date, handling any requests or incidents calmly, and making sure your policies aren’t just sitting in a drawer. Much of that becomes far simpler with a GDPR policy starter pack to build from, rather than starting with a blank page.
If you do appoint a DPO, voluntarily or because you must
Once you appoint a statutory DPO, real conditions attach to the role, and you have to meet them whether you appointed one by choice or by law.
It’s worth knowing this, because some businesses appoint a DPO voluntarily and are surprised that the legal requirements then apply in full. The ICO is explicit that a voluntary DPO must be treated exactly as a mandatory one. If you give someone the formal DPO title, UK GDPR expects you to:
- Let them act independently. The DPO can’t be told how to do their data protection job, and can’t be penalised or dismissed for doing it properly.
- Resource them adequately. That means enough time, budget and support to do the role and keep their knowledge current, scaled to how complex and sensitive your processing is.
- Give them a direct line to the top. The DPO must be able to report to your highest management level.
- Avoid a conflict of interest. Their other duties mustn’t clash with their oversight role. The person who decides how data is used generally can’t also be the independent person checking that it’s done lawfully.
The role can be filled internally by an existing employee, or outsourced to an external provider on a service contract. Plenty of small organisations that do need one choose the outsourced route, because it brings independent expertise without a full-time hire. Either way, the conditions above still apply.
Don’t let the DPO question stall the basics
Whether or not you need a DPO, the foundations of data protection are the same, and they’re what genuinely reduce your risk.
Here’s the honest bit. “Do I need a DPO?” can quietly become an excuse to do nothing, as if the answer changes everything. It doesn’t. Whether you’re legally required to appoint a DPO or not, the same fundamentals apply to every business: know what personal data you hold, hold only what you need, keep it secure, be straight with people about how you use it, and be ready to respond if something goes wrong.
For the overwhelming majority of small businesses, the answer to the DPO question is simply “no, but make sure someone owns this.” Settle that quickly, point that person at the practical work, and you’ve spent your energy where it actually counts — on protecting data, not on a job title most of you don’t need.
SecurSentry is launching soon to help UK SMEs build genuine, evidence-backed data protection — including naming who’s responsible and getting the everyday basics in place — without needing a DPO or a legal team to do it. Join the waitlist to be first to know when we open.
This article is general information, not legal or compliance advice. If your business involves large-scale monitoring or sensitive data, or you’re unsure which side of the line you fall on, seek qualified guidance from a data protection professional or solicitor.